Last updated: September 2026
This app was built to hold some of the most sensitive information a person has — a will, account passwords, letters to family. This policy explains exactly what leaves your device, and what never does.
Your Vault items (documents, passwords, secure notes), Letters, and Checklist, plus the encryption key used to seal that content (stored in the device Keychain, gated by Face ID or Touch ID). None of this requires an account or an internet connection, and it never leaves your device unless you turn on emergency access.
Email address — collected only if you use the Executor feature, to create an account (via a passwordless sign-in link) so we know who you and your executor are for the access-request handshake.
Encrypted vault content — if you set up an executor, your Vault and Letters content is encrypted on your device and the resulting ciphertext is stored on our servers so it can be recovered even if your device is lost. The encryption key is separately wrapped for each executor using public-key cryptography generated on their own device — we store only that wrapped key, never a form of it we could decrypt ourselves.
Check-in and access-request timestamps — when you tap "Check In," and when an executor requests access, we record the time. This is what makes the waiting-period safeguard work.
No advertising, ad tracking, or ad SDKs. No analytics that identify you personally. No selling or sharing your data with third parties. No access to your Vault contents by us — see below.
Every Vault item and Letter is sealed on your device using a randomly generated key before it's ever written to disk or synced anywhere. That key lives in your device's Keychain, protected by Face ID or Touch ID. When you invite an executor, their device generates its own private key that never leaves their phone; your device uses their matching public key to wrap a copy of your encryption key, and that wrapped copy — not the key itself — is what we store. We physically cannot decrypt your Vault. Only your device, or an executor's device after an approved request, can.
Uninstalling the app removes everything stored on your device. If you also created an account for emergency access, go to the Executor tab → Account → Delete Account to permanently remove your email, encrypted vault backup, and access history from our servers — this happens immediately and cannot be undone.
We use Supabase to host the optional emergency-access data described above, and Apple's App Store / StoreKit to process subscription payments — we never see or store your payment details ourselves.
If this policy changes, the update will be posted on this page.